Security & Responsible Disclosure
How to report a security vulnerability in Sojial.
Status: Reviewed · public-launch ready (GO) · Last updated: 2026-06-18
Reporting a vulnerability
Email security@sojial.com with enough detail to reproduce the issue. Please give us reasonable time to investigate and fix before any public disclosure, and avoid accessing or modifying other people's data.
Scope
In scope: vulnerabilities affecting sojial.com, its authentication flows, account security, data-access controls, media storage, API endpoints and production infrastructure operated directly for Sojial. Out of scope: social engineering, physical attacks, denial-of-service, spam, destructive testing, and access to third-party accounts without consent.
What to expect
No public bug-bounty programme is offered at launch. Responsible disclosure is welcome via security@sojial.com. Reporters must act in good faith, avoid privacy violations and data destruction, stop testing once a vulnerability is confirmed, and provide enough detail to reproduce and fix the issue.
Contact
Security reports: security@sojial.com